ScreenOS:Trust Zone - TCP Reset

Information

Activating the zone wide TCP Reset setting for the Trust zone will reset connection that have either timeout out or when a host attempt to connect on a service that is not allowed due to configuration. If the firewall times out an inactive session but a host still marks the session as up, when the host next attempts to communication it will receive a TCP Reset. The TCP Reset will cause the host to reinitialize the TCP 3-Way handshake for a new session instead of repeatably attempting to communication on a session the firewall has timed out.

Solution

You may navigate to the following ScreenOS menu location: Configuration > Network > Zones. Once there you may select the appropriate zone to further edit.

See Also

https://www.juniper.net/techpubs/en_US/screenos6.3.0/information-products/pathway-pages/screenos/index.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-10

Plugin: Juniper

Control ID: 0507d69cb7bf4c6ab28061428ef91ecbbdcbb56a683650ca07ea992a2ca23101